ZeroHour

News

10 stories in the last 3d

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

CISA and NIST published NIST IR 8587, final guidance for protecting identity tokens from forgery, theft, replay, and signing-key compromise.

NIST Interagency Report 8587 (September 15, 2026) expands the IA-13 'Identity Providers and Authorization Servers' control from NIST SP 800-53 R5.1.1, guiding federal agencies and cloud providers on SSO, identity federation, and machine-to-machine authentication. It requires hardware-backed signing-key storage for moderate-impact systems, 90-day key rotation for high-impact systems, token lifetimes under one hour, and sender-constrained mechanisms such as mutual TLS and DPoP. The report cites incidents including forged SAML assertions that exposed over 60,000 emails from a federal agency. It also extends guidance to agentic AI systems using signed tokens and urges post-quantum cryptography migration planning.

Cyber Security News · 5h agoAdvisory

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory

CISA and five international agencies publish joint guidance detailing 17 techniques attackers use to compromise Microsoft Active Directory environments.

CISA, NSA, and the Australian Signals Directorate's ACSC, with contributions from Canadian, UK, and New Zealand cyber centers, released technical guidance on 17 Active Directory attack techniques. It covers AD Domain Services, AD Certificate Services, and AD Federation Services, including Kerberoasting, DCSync, Golden Ticket, Golden SAML, Skeleton Key, and Shadow Credentials. The guidance recommends treating domain controllers, CAs, AD FS servers, and Entra Connect systems as Tier 0 assets with phishing-resistant MFA, Kerberos pre-authentication enforcement, and disabling NTLM/SMBv1.

Cyber Security News · 6h agoAdvisory

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

NIST and CISA publish final interagency report with implementation guidance for protecting tokens and assertions from forgery and misuse.

CISA released a final NIST/CISA interagency report guiding federal agencies and cloud service providers on protecting identity assertions, access tokens, and cryptographic mechanisms underlying modern authentication and authorization. It addresses forgery, theft, and misuse of signed tokens that adversaries use for lateral movement and data access in hybrid and multi-cloud, SSO, federation, and API-based environments. The final version updates token validation, secrets management, and detection-at-scale guidance gathered via the Joint Cyber Defense Collaborative, and supports Executive Order 14306 and Secure by Design principles.

CISA Advisories · 10h agoAdvisory

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 1d agoAdvisory

App Store Connect Update

Apple issued an App Store Connect update with release notes published on its developer site.

Apple announced an update to App Store Connect, its developer tool for managing App Store submissions. No security fixes, CVEs, or notable changes were described in the announcement.

Apple software releases · 1d agoAdvisory 2 sources

tvOS 27.0 (24J361)

Apple released tvOS 27.0 (build 24J361) with no security fixes detailed in the announcement.

Apple published tvOS 27.0 (24J361) on its developer news feed. The notice contains only download and release-note links with no security content described. Any security fixes would be listed in the full release notes.

Apple software releases · 1d agoAdvisory

Xcode 27 (27A266a)

Apple released Xcode 27 (build 27A266a) with no security fixes detailed in the announcement.

Apple published Xcode 27 (27A266a) on its developer news feed. The notice contains only download and release-note links. No security content is described in the announcement itself.

Apple software releases · 1d agoAdvisory 2 sources

iOS 27.0 (24A437)

Apple released iOS 27.0 (build 24A437) with no security fixes detailed in the announcement.

Apple published iOS 27.0 (24A437) on its developer news feed. The notice only links to downloads and release notes with no security content described. iOS major-version drops commonly bundle security fixes, so release notes should be reviewed.

Apple software releases · 1d agoAdvisory 3 sources1

watchOS 27.0 (24R364)

Apple released watchOS 27.0 (build 24R364) with no security fixes detailed in the announcement.

Apple published watchOS 27.0 (24R364) on its developer news feed. The notice contains only download and release-note links with no security content described. Defenders should check the release notes for any security fixes.

Apple software releases · 1d agoAdvisory

macOS 27.0 (26A428)

Apple released macOS 27.0 (build 26A428) with no security fixes detailed in the announcement.

Apple published macOS 27.0 (26A428) on its developer news feed. The notice only links to downloads and release notes without describing security updates. macOS major releases typically include security fixes detailed in separate notes.

Apple software releases · 1d agoAdvisory 2 sources